Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo MAINFREIGHT.COM

Group: Clop

Discovered by ransomware.live: 2025-02-27

Estimated attack date: 2025-02-27

Country: NZ

Description:

[AI generated] Mainfreight Ltd is a global logistics and freight company headquartered in New Zealand. The company specializes in managed warehousing and international and domestic freight forwarding. Mainfreight offers comprehensive logistic solutions, including supply chain management and specialized freight like hazardous substances and perishables. Its footprint spans Oceania, Asia, Europe, and the Americas, with a strong commitment to sustainable practices.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 70

Third Party Employee Credentials: 13


External Attack Surface: 22



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domains@melbourneit.au
  • abuse@melbourneit.com.au
MX Records
  • au-smtp-inbound-2.mimecast.com.
  • au-smtp-inbound-1.mimecast.com.
TXT Records
  • QuoVadis=682205cc-e46b-4690-9ee5-39a32c885c89
  • Foxit-domain-verification=1ade1d22b853874c43db237056f89243
  • v=spf1 ip4:192.254.121.248 ip4:203.174.30.0/23 ip4:13.88.113.130 ip4:13.88.116.145 include:spf-ip.mainfreight.com include:spf-cwip.mainfreight.com include:au._netblocks.mimecast.com include:spf.protection.outlook.com include:servers.mcsv.net include:_phi" "shspf.knowbe4.com include:spf-mfteu.mainfreight.com -all
  • Ez9-KwX-9Jq
  • 5878g6m6mm8ukvrvcg203bb6f5
  • 0vmgczsf1w4c89nhw5jk5b78ljrr1pt9
  • MS=ms82209141
  • google-site-verification=e8crlil1VqFwAJn7cYVW_yuKdot5fw9IUaSowHQjQSE
  • _mgj62q3btqts3t0ze7keek3ktuvbs1m
  • teamviewer-sso-verification=fc0b20243ec842ee91e246d012a92ba4
  • globalsign-domain-verification=0E119296EB28628685484F00E8DC7323
  • 41af7e187f933a0c94c7093d3cca36daeacbefdc8555063934
  • k7fd2n03xxt4ttqwt7n8g0v4dww2f5y5
  • google-site-verification=YqX9b-wd2HFfy-cH9R3JsD6K6PpCxXFEoYFH3BLNoVQ
  • ciscocidomainverification=5f19cbb7b2f69bcbfcc42ca4bf4f51a426f251809729f8e148b342e39a11752b
  • qase-c88ad412a65f080c0572141f58afbe5809b03914
  • 8bd7a6f4-4f7b-4d12-a537-49d83b49f4cd
  • Foxit-domain-verification=8488daf3871195fad9254e95437158dc
  • 8ftmbw0t832msm86ks3lhl65gmwkqlwr
  • _5jfmd4kj1wfceqnj4v84tqeb7v7td79
  • knowbe4-site-verification=c1e039a1a450b2db6349868f94ad1445
  • c4gg5sh1k8nd8tkvcj7skpjxj4qd8sg5
  • logmein-verification-code=h4x3zFgidw3SnbOn5aKvCyq49
Cloud / SaaS Services Detected
Mailchimp Microsoft 365 LogMeIn Teamviewer KnowBe4 Mimecast